By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: Telus tells customers their accounts were raided with stolen passwords
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
Telus tells customers their accounts were raided with stolen passwords
News & Alerts

Telus tells customers their accounts were raided with stolen passwords

Canada's Telus says attackers used stolen credentials to reach customer records over more than a year.

CSBadmin
Last updated: September 14, 2026 11:15 pm
CSBadmin
2 Min Read
Share
SHARE

Some Telus subscribers are being told that intruders sat inside their accounts for over a year using stolen passwords; Telus is one of Canada’s biggest telecom carriers.

Notices sent to affected consumer telecom subscribers put the intrusion window at February 2025 through June 2026. The attackers reached names, account and phone numbers, billing addresses, email addresses, partial payment card numbers, subscription details, and payment history.

Telus said the lifted data has been used to try to talk customers into moving their services to competitors, and that some victims had their accounts altered without permission. No account count has been disclosed.

Compromised credentials have been reset and monitoring layered onto the affected accounts, Telus said. The carrier also alerted the Vancouver Police Department and extended identity theft protection to victims.

The sparse description points to credential stuffing or another account-takeover campaign fed by passwords pulled from a third party, though Telus has not said the abused passwords came from outside its own systems.

The disclosure adds to a bruising stretch for the carrier. March brought a separate admission from subsidiary Telus Digital, after the ShinyHunters crime group said it had taken about a petabyte of data.

For subscribers, the practical steps are unchanged: rotate passwords, turn on a second factor, and treat cold calls about a phone or internet plan as suspect.

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverCanadacredential stuffingdata breachTelecomTelus
SOURCES:SecurityWeek
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article A Twitch viewer add-on slipped 31,000 session tokens to a bot service A Twitch viewer add-on slipped 31,000 session tokens to a bot service
Next Article Britain nudges 23 million One Login users toward passkeys Britain nudges 23 million One Login users toward passkeys

Trending

A fake Cloudflare page on an Indian IT agency site pushed terminal commands
Fake Cloudflare page on Indian IT agency site pushed terminal commands
September 14, 2026
AWS benchmark finds AI code scanners drown in false alarms
AWS benchmark finds AI code scanners drown in false alarms
September 14, 2026
Britain nudges 23 million One Login users toward passkeys
Britain nudges 23 million One Login users toward passkeys
September 14, 2026
A Twitch viewer add-on slipped 31,000 session tokens to a bot service
A Twitch viewer add-on slipped 31,000 session tokens to a bot service
September 14, 2026
Microsoft moves Teams and M365 web users to new domains
Microsoft moves Teams and M365 web users to new domains
September 13, 2026

Related Stories

CSBadmin

BMC research finds 24,650 servers leaking password hashes

CSBadmin

Ivanti ITSM Flaw Opens Door to Full Admin Takeover

CSBadmin

Fake Security Tool Sites Deliver Stealth Malware to Researchers

CSBadmin

Chinese Silver Fox Group Uses Tax Phishing to Deliver New ABCDoor Backdoor

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.